Back to Frameworks

UN Guiding Principles on Business and Human Rights (UNGPs)

International (United Nations)
v2011
8 domains
26 controls

The United Nations Guiding Principles on Business and Human Rights (UNGPs), unanimously endorsed by the UN Human Rights Council in 2011, establish the authoritative global standard for preventing and addressing human rights impacts linked to business activity. The UNGPs rest on three pillars: the State duty to protect human rights, the corporate responsibility to respect human rights, and access to remedy. The corporate responsibility pillar requires human rights due diligence - a process to identify, prevent, mitigate, and account for adverse human rights impacts. The UNGPs inform mandatory human rights due diligence legislation globally (EU CSDDD, German LkSG, French Loi de Vigilance).

Verified

UN Guiding Principles on Business and Human Rights (UNGPs) is a compliance framework from International (United Nations) with 8 domains and 26 controls that map to 52 other frameworks. The largest domains are Pillar I: State Duty to Protect Human Rights (8 controls), Pillar II: Corporate Responsibility to Respect Human Rights (6 controls), Human Rights Due Diligence (5 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (8)

Human Rights Due Diligence

5 controls

Human Rights Due Diligence

Controls in the Human Rights Due Diligence domain of UN Guiding Principles on Business and Human Rights (UNGPs)5 controls
CodeTitle
UNGP-17Human Rights Due Diligence
UNGP-18Assessing Actual and Potential Impacts
UNGP-19Integrating and Acting Upon Findings
UNGP-20Tracking Effectiveness of Responses
UNGP-21Communicating Externally on Human Rights

Pillar I: State Duty to Protect Human Rights

8 controls

Pillar I: State Duty to Protect Human Rights

Controls in the Pillar I: State Duty to Protect Human Rights domain of UN Guiding Principles on Business and Human Rights (UNGPs)8 controls
CodeTitle
UNGP-1State Duty to Protect Against Human Rights Abuses
UNGP-2State Expectations of Business Enterprises Abroad
UNGP-3State Regulatory and Policy Functions
UNGP-4State-Business Nexus
UNGP-5Privatised Public Services and Human Rights Oversight
UNGP-6Public Procurement and Human Rights
UNGP-7Supporting Business Respect in Conflict Affected Areas
UNGP-8Policy Coherence Across Government

Pillar II: Corporate Responsibility to Respect Human Rights

6 controls

Pillar II: Corporate Responsibility to Respect Human Rights

Controls in the Pillar II: Corporate Responsibility to Respect Human Rights domain of UN Guiding Principles on Business and Human Rights (UNGPs)6 controls
CodeTitle
UNGP-11Corporate Responsibility to Respect Human Rights
UNGP-12Scope of Human Rights to Be Respected
UNGP-13Three Ways Businesses May Be Involved With Impacts
UNGP-14Applies to All Enterprises Regardless of Size
UNGP-15Knowing and Showing - Policies and Processes
UNGP-16Policy Commitment Standards

Pillar III: Access to Remedy

3 controls

Pillar III: Access to Remedy

Controls in the Pillar III: Access to Remedy domain of UN Guiding Principles on Business and Human Rights (UNGPs)3 controls
CodeTitle
UNGP-22Remediation Where Cause or Contribution Identified
UNGP-29Operational Level Grievance Mechanisms
UNGP-31Effectiveness Criteria for Non-Judicial Grievance Mechanisms

Protect

1 controls
Controls in the Protect domain of UN Guiding Principles on Business and Human Rights (UNGPs)1 controls
CodeTitle
UNGPBHR-1Pillar I: State Duty to Protect Human Rights

Remedy

1 controls
Controls in the Remedy domain of UN Guiding Principles on Business and Human Rights (UNGPs)1 controls
CodeTitle
UNGPBHR-3Pillar III: Access to Remedy

Reporting

1 controls
Controls in the Reporting domain of UN Guiding Principles on Business and Human Rights (UNGPs)1 controls
CodeTitle
UNGPBHR-4Reporting and Communication

Respect

1 controls
Controls in the Respect domain of UN Guiding Principles on Business and Human Rights (UNGPs)1 controls
CodeTitle
UNGPBHR-2Pillar II: Corporate Responsibility to Respect Human Rights

Your Compliance Coverage

If you comply with UN Guiding Principles on Business and Human Rights (UNGPs), you already cover:

Maps to 52 other frameworks

26 total controls
Fair Labor Association (FLA) Workplace Code of Conduct
7 source controls mapped|12 target controls covered
27%
Extractive Industries Transparency Initiative (EITI) Standard (2023)
5 source controls mapped|3 target controls covered
19%
Ethical Trading Initiative (ETI) Base Code
4 source controls mapped|4 target controls covered
15%
Equator Principles (EP4, 2020)
4 source controls mapped|2 target controls covered
15%
FATF 40 Recommendations
1 source controls mapped|1 target controls covered
4%
OECD Recommendation on Artificial Intelligence (2024 Update)
1 source controls mapped|2 target controls covered
4%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|1 target controls covered
4%
ISO/IEC 29147:2018
1 source controls mapped|2 target controls covered
4%
ISO/IEC 27011:2024
1 source controls mapped|1 target controls covered
4%
BSI IT-Grundschutz
1 source controls mapped|1 target controls covered
4%
ISO/IEC 29134:2023
1 source controls mapped|1 target controls covered
4%
ISO/IEC 30111:2019
1 source controls mapped|1 target controls covered
4%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|1 target controls covered
4%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|1 target controls covered
4%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|1 target controls covered
4%
ISMAP (Japan)
1 source controls mapped|1 target controls covered
4%
Japan FSA Cybersecurity Guidelines for Financial Institutions
1 source controls mapped|1 target controls covered
4%
MITRE ATT&CK
1 source controls mapped|1 target controls covered
4%
Modern Slavery Act 2018 (Australia)
1 source controls mapped|1 target controls covered
4%
MTCS (Singapore)
1 source controls mapped|1 target controls covered
4%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|1 target controls covered
4%
New Zealand Information Security Manual (NZISM)
1 source controls mapped|1 target controls covered
4%
NIS2 Directive Implementing Acts
1 source controls mapped|1 target controls covered
4%
NIST Privacy Framework
1 source controls mapped|1 target controls covered
4%
NIST SP 800-123
1 source controls mapped|1 target controls covered
4%
NIST SP 800-137
1 source controls mapped|1 target controls covered
4%
NIST SP 800-144
1 source controls mapped|1 target controls covered
4%
NIST SP 800-145
1 source controls mapped|1 target controls covered
4%
NIST SP 800-146
1 source controls mapped|1 target controls covered
4%
NIST SP 800-61
1 source controls mapped|1 target controls covered
4%
NIST SP 800-63-4
1 source controls mapped|1 target controls covered
4%
NIST SP 800-88
1 source controls mapped|1 target controls covered
4%
NIST SP 800-92
1 source controls mapped|1 target controls covered
4%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
1 source controls mapped|1 target controls covered
4%
OECD AI Principles
1 source controls mapped|1 target controls covered
4%
ICMM Mining Principles (2024 Update)
1 source controls mapped|1 target controls covered
4%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|3 target controls covered
4%
UK FCA/PRA Operational Resilience Framework
1 source controls mapped|1 target controls covered
4%
TSA Pipeline Cybersecurity Directives
1 source controls mapped|1 target controls covered
4%
SLSA
1 source controls mapped|1 target controls covered
4%
SIG (Shared Assessments)
1 source controls mapped|1 target controls covered
4%
Secure by Design: A Guide for Manufacturers (CISA)
1 source controls mapped|2 target controls covered
4%
SA8000:2014 - Social Accountability Standard
1 source controls mapped|1 target controls covered
4%
PTES
1 source controls mapped|1 target controls covered
4%
OWASP SAMM
1 source controls mapped|1 target controls covered
4%
OWASP MASVS
1 source controls mapped|1 target controls covered
4%
OpenSSF Scorecard
1 source controls mapped|1 target controls covered
4%
O-RAN WG11 Security Specification
1 source controls mapped|1 target controls covered
4%

What is UN Guiding Principles on Business and Human Rights (UNGPs) and who does it apply to?

UN Guiding Principles on Business and Human Rights (UNGPs) is a compliance framework from International (United Nations) with 8 domains and 26 controls. The United Nations Guiding Principles on Business and Human Rights (UNGPs), unanimously endorsed by the UN Human Rights Council in 2011, establish the authoritative global standard for preventing and addressing human rights impacts linked to business activity. The UNGPs rest on three pillars: the State duty to protect human rights, the corporate responsibility to respect human rights, and access to remedy. The corporate responsibility pillar requires human rights due diligence - a process to identify, prevent, mitigate, and account for adverse human rights impacts. The UNGPs inform mandatory human rights due diligence legislation globally (EU CSDDD, German LkSG, French Loi de Vigilance). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does UN Guiding Principles on Business and Human Rights (UNGPs) actually require?

UN Guiding Principles on Business and Human Rights (UNGPs) has 26 controls organised across 8 domains. The largest domains are Pillar I: State Duty to Protect Human Rights (8 controls), Pillar II: Corporate Responsibility to Respect Human Rights (6 controls), Human Rights Due Diligence (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of UN Guiding Principles on Business and Human Rights (UNGPs) do I already cover?

UN Guiding Principles on Business and Human Rights (UNGPs) maps to 52 other compliance frameworks. The top mapping partners are Fair Labor Association (FLA) Workplace Code of Conduct (27% coverage), Extractive Industries Transparency Initiative (EITI) Standard (2023) (19% coverage), Ethical Trading Initiative (ETI) Base Code (15% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement UN Guiding Principles on Business and Human Rights (UNGPs)?

Start your UN Guiding Principles on Business and Human Rights (UNGPs) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UN Guiding Principles on Business and Human Rights (UNGPs) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 26 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required